AppSecNews
SAST Open source and commercial Established

Codacy

by Codacy

A code quality platform that orchestrates open-source linters and security analyzers, normalizes their output, and enforces standards on pull requests.

Visit codacy.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Codacy in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Current set of bundled analyzers and any first-party engines: confirm with vendor docs

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Codacy is primarily an orchestration and normalization layer. Rather than shipping one analysis engine, it runs a collection of established open-source tools against your repository, each packaged as a container: ESLint, PMD, Pylint, Bandit, Brakeman, Semgrep-style pattern engines, plus duplication and complexity metrics. The output of all of them is mapped onto a common issue model with a category, a severity and a pattern identifier, so a Python security finding and a JavaScript style finding sit in the same queue with the same workflow.

On top of that it maintains per-repository quality gates. You define thresholds for new issues, coverage delta, duplication and complexity, and Codacy posts a status check on each pull request evaluated against the diff rather than the whole repository. That diff-scoped evaluation is what makes it usable on legacy code: existing debt does not block merges, new debt does. A CLI runs the same analyzer set locally or in a pipeline of your choosing, licensed under AGPL.

Where it fits

This lives at the pull request. Developers are the primary audience and engineering managers are usually the buyer, with security as one category among several. It integrates at the Git provider level, so setup is mostly granting access to repositories rather than editing pipeline files. It is most useful when a team has already agreed on a standard and wants it enforced consistently; it will not help a team that has not decided what good looks like.

Strengths

  • One dashboard and one workflow across many languages and many underlying linters, which removes a lot of per-repository tooling sprawl.
  • Diff-based gating makes adoption on an existing codebase practical rather than theoretical.
  • Coverage, duplication and complexity sit next to security findings, which suits teams treating quality and security as one conversation.
  • Self-hosted deployment is available for organizations that cannot send source off site.

Limitations

  • Security depth is bounded by the underlying open-source analyzers. There is no cross-file taint engine here, so it will miss classes of flaws that a dedicated SAST product finds.
  • Aggregating many linters means aggregating their false positives, and the initial noise on a mature repository is substantial until patterns are disabled.
  • It is a quality tool with security coverage rather than a security tool, which matters if an auditor asks what scanner you use.

Who it suits

Good for engineering organizations that want consistent standards across many repositories and languages without running their own linter infrastructure. Less appropriate as the primary control for a team whose main obligation is finding exploitable vulnerabilities, where a purpose-built taint-analysis scanner should own that job and Codacy handles the quality layer beside it.

Used Codacy? Recommend it under your own name and title.

Recommend this tool